<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LDAP Import of nested groups in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/ldap-import-of-nested-groups/m-p/232103#M185233</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Thanks for the help.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Can I just confirm what you are saying?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;You say that if I place all the groups I need, directly under the Alfresco Master Group, it should work?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I would agree with this based on what i have seen so far.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The way it stands at the moment is, I import the Alfresco Master Group and those groups directly inside that group get populated with users.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The groups within the Alfresco Master Group that conatin sub groups do not get populated with those subgroups which is due to the fact that you say &lt;/SPAN&gt;&lt;EM&gt;memberOf &lt;/EM&gt;&lt;SPAN&gt;is not recursive.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Is there any other way around adding all groups directly under the Master Group? Changing the AD directory structure might not be feasible.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Can the query be edited to recrsively go through the groups?&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 25 Mar 2010 15:40:04 GMT</pubDate>
    <dc:creator>cnihill</dc:creator>
    <dc:date>2010-03-25T15:40:04Z</dc:date>
    <item>
      <title>LDAP Import of nested groups</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ldap-import-of-nested-groups/m-p/232101#M185231</link>
      <description>Hi,I am looking to import a master group to Alfresco using an LDAP query. The master group contains 4 groups, one of which contains 17 other groups.At the moment, when I run this query to import the master group, the four groups get imported but the 17 sub groups of one of those groups do not.The on</description>
      <pubDate>Thu, 25 Mar 2010 11:31:41 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ldap-import-of-nested-groups/m-p/232101#M185231</guid>
      <dc:creator>cnihill</dc:creator>
      <dc:date>2010-03-25T11:31:41Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Import of nested groups</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ldap-import-of-nested-groups/m-p/232102#M185232</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Yes, LDAP import of hierarchical group structures is possible, but not if you restrict your LDAP queries like this!&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;In Active Directory, the memberOf attribute it not recursive - it only lists the groups that a group or user is a direct member of.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;So you are going to have to find another way to restrict your user and group queries. If "Alfresco Master Group" really is the set of all groups that should be displayed in Alfresco, then perhaps you could directly add all groups and users that you want to show up to this group? Within this group, you could still have nested structures. All the inter-relationships between groups will still be picked up.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Mar 2010 12:17:09 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ldap-import-of-nested-groups/m-p/232102#M185232</guid>
      <dc:creator>dward</dc:creator>
      <dc:date>2010-03-25T12:17:09Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Import of nested groups</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ldap-import-of-nested-groups/m-p/232103#M185233</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Thanks for the help.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Can I just confirm what you are saying?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;You say that if I place all the groups I need, directly under the Alfresco Master Group, it should work?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I would agree with this based on what i have seen so far.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The way it stands at the moment is, I import the Alfresco Master Group and those groups directly inside that group get populated with users.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The groups within the Alfresco Master Group that conatin sub groups do not get populated with those subgroups which is due to the fact that you say &lt;/SPAN&gt;&lt;EM&gt;memberOf &lt;/EM&gt;&lt;SPAN&gt;is not recursive.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Is there any other way around adding all groups directly under the Master Group? Changing the AD directory structure might not be feasible.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Can the query be edited to recrsively go through the groups?&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Mar 2010 15:40:04 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ldap-import-of-nested-groups/m-p/232103#M185233</guid>
      <dc:creator>cnihill</dc:creator>
      <dc:date>2010-03-25T15:40:04Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Import of nested groups</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ldap-import-of-nested-groups/m-p/232104#M185234</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Change your query to this:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ##groupQuery&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ##Inserting the master group here&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ldap.synchronization.groupQuery=(&amp;amp;(objectclass\=group)(memberOf:1.2.840.113556.1.4.1941:\=CN=Alfresco Master Group,OU=User Groups,OU=ICTL,OU=Master Groups,DC=Domain,DC=ie))&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ##differential Group Query&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ldap.synchronization.groupDifferentialQuery=(&amp;amp;(objectclass\=group)(memberOf:1.2.840.113556.1.4.1941:\=CN=Alfresco Master Group,OU=User Groups,OU=ICTL,OU=Master Groups,DC=Domain,DC=ie))&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;Notice the &lt;/SPAN&gt;&lt;STRONG&gt;:1.2.840.113556.1.4.1941:&lt;/STRONG&gt;&lt;SPAN&gt; added in after the memberOf in each query.&amp;nbsp; This is the LDAP_MATCHING_RULE_IN_CHAIN modifier - &lt;/SPAN&gt;&lt;A href="http://msdn.microsoft.com/en-us/library/aa746475%28v=vs.85%29.aspx" rel="nofollow noopener noreferrer"&gt;http://msdn.microsoft.com/en-us/library/aa746475%28v=vs.85%29.aspx&lt;/A&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Mar 2011 21:29:51 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ldap-import-of-nested-groups/m-p/232104#M185234</guid>
      <dc:creator>brazen</dc:creator>
      <dc:date>2011-03-11T21:29:51Z</dc:date>
    </item>
  </channel>
</rss>

